This is the guide that I used to set up my tunnels. We have three site to site tunnels in a hub a spoke configuration. The note at the bottom of the article explains how to modify the config for multiple tunnels on the same interface. Basically your are creating two crypto maps with the same name but different priorities.

I understand the guide, my issue is what do I need to do if I need to change step 1 too ? ( I see that note ask us repeat 2-7). Should I just keep going on as usual (two crypto maps with same name, but different priorities)?

I'm not sure why that guide ties policy number 9 to pre-shared key usage. You can repeat step 1 and use the parameters you need, just with a different policy number. Negotiation starts with the lowest policy number until a match is found. The following should work for what you specified.

OK.. I added a new crypto map entry with different (lesser) priority to the same map. Is it automatic that the new policy will kick or do I need to take off the cypto map association to the gi interface (WAN link) and add it back? I did not want to disturb the existing ipsec tunnels with other customer.